From Intelligence Gathering to Financial Gain: Countering DPRK Cyber Operations

2025-11-01 CGAI

https://www.cgai.ca/pp_kim_nov2025

Thumbnail for From Intelligence Gathering to Financial Gain: Countering DPRK Cyber Operations

Dr. Julie Kim's paper traces North Korea's cyber operations from intelligence collection against officials, academics, journalists, defectors, and defense targets toward sanctions-driven revenue generation. It links cryptocurrency theft and overseas IT worker income to funding for WMD and ballistic missile programs, citing the regime's use of cyber activity as a broader military and defense security threat. The source describes the Reconnaissance General Bureau as the likely core institution behind DPRK cyber operations, with an estimated force of about 7,000 hackers and additional IT workers concealing their identities. It also highlights newer risks from generative AI, Research Center 227, social engineering, and the need for intelligence sharing and joint cyber exercises among like-minded countries.

Related Reports

« Back